Junglewise Threat Intelligence

CVE-2026-69580: Microsoft Windows Biometric Service heap buffer overflow

CVE-2026-69580 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows Biometric Service. Vendors: Microsoft.

Executive brief

Windows Biometric Service is a system component that manages fingerprint and other biometric authentication data. A heap buffer overflow vulnerability allows an authenticated local user to crash the service or execute arbitrary code with elevated privileges, potentially leading to full system compromise.

Technical details

A heap-based buffer overflow exists in the Windows Biometric Service, allowing an authorized local attacker to trigger a memory corruption condition. The vulnerability requires local access and prior authentication. Successful exploitation allows an attacker to execute arbitrary code in the context of the privileged service, achieving local privilege escalation. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Biometric Service

Timeline

  • 2026-09-08: disclosed

References

Related threats